OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: Possible new Korgo variant. WAS: New SDBot variant

From: Nick FitzGerald (nickvirus-l.demon.co.uk)
Date: Tue Aug 10 2004 - 19:48:29 CDT


Christopher Harrington wrote:

> This appears to be a new Korgo variant based on the similarities in
> behaviors, not an SDbot.
>
> 1. It uses the LSASS vuln to spread.
> 2. It connects to IRC.
> 3. It listens on port 113.
>
> Stay tuned.....

Instead of just guessing and messing around with this by yourself, had
you considered sending it to major antivirus developers so they can get
detection of it out (if, in fact, it is widely unknown)??

To save you looking them up, here are the sample submission addresses
of the better-known AV developers. I'd suggest that you send the
suspect file(s) to several of these you consider trustworthy...

   Authentium (Command Antivirus) <virusauthentium.com>
   Computer Associates (US) <virusca.com>
   Computer Associates (Vet/EZ) <supportvet.com.au>
   DialogueScience (Dr. Web) <Antivirdials.ru>
   Eset (NOD32) <samplenod32.com>
   F-Secure Corp. <samplesf-secure.com>
   Frisk Software (F-PROT) <viruslabf-prot.com>
   Grisoft (AVG) <virusgrisoft.cz>
   H+BEDV (AntiVir, Vexira engine) <virusantivir.de>
   Kaspersky Labs <newviruskaspersky.com>
   Network Associates (McAfee) <virus_researchnai.com>
     (use a ZIP file with the password 'infected' without the quotes)
   Norman (NVC) <analysisnorman.no>
   Panda Software <labspandasoftware.com>
   Sophos Plc. <supportsophos.com>
   Symantec (Norton) <avsubmitsymantec.com>
   Trend Micro (PC-cillin) <virus_doctortrendmicro.com>
     (Trend may only accept files from users of its products)

--
Nick FitzGerald
Computer Virus Consulting Ltd.
Ph/FAX: +64 3 3529854